UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS
ID: 5c3efcf4-3186-52af-a413-a4d571f25c77
STIX ID: report--5c3efcf4-3186-52af-a413-a4d571f25c77
Feed Name: cybersecurityNews.com
**Executive summary:** A regionally focused campaign observed from late 2025 through early 2026 targets unpatched IIS servers in Thailand and Vietnam using injected web shells and PowerShell to deploy BadIIS variants (with country tags) and the GotoHTTP RAT; attackers create hidden admin accounts (e.g., admin$, mysql$, admin1$), use anti-forensic utilities (Sharp4RemoveLog, CnCrypt Protect, OpenArk64), and tailor payloads by Accept-Language filtering to enable SEO fraud and persistent remote access, with Cisco Talos noting overlap with the WEBJACK operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
